Lead Security Operation Engineer positions focus on delivering results in their domain. This page aggregates open Lead Security Operation Engineer roles and what employers typically expect.
About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’. The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years. Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together. About the role We're looking for a Lead Security Operations Engineer to join our Cybersecurity team at Pleo. In this role, you'll define and deliver the SecOps roadmap, building the detection, response, and investigation capability that protects a fast-growing fintech. If you're excited about owning a security operations function end to end, from framework-based strategy through to the code that makes it run, then this is the opportunity for you! Who you'll be working with and reporting to You'll report to our VP of Fraud & Security and work closely with Fraud, DevSecOps, Engineering, and Risk & Compliance. Our team is highly collaborative and dedicated to protecting Pleo's customers and their money. You'll also have the chance to partner with teams across the organisation and to bring less experienced security engineers up with you as the function matures. What you'll be doing As a Lead Security Operations Engineer, you will: Build and own a structured SecOps roadmap grounded in well-known frameworks such as MITRE ATT&CK, NIST, and CIS benchmarks. Lead security investigations and digital forensics, from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent. Design, tune, and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isn't lost in the noise. Strengthen our perimeter and authentication posture, including WAF configuration, authorisation tuning, and monitoring for suspicious traffic. Protect sensitive data through DLP controls, and make sure the coverage matches where the data actually lives. Improve our on-call rotation for the team, defining the alerting, escalation paths, and response SLAs that make it work. Automate detection and response workflows, using code and AI to reduce manual toil and shorten time to resolution. Reduce SecOps-attributed risk identified through compliance gaps, and collect the evidence that demonstrates it. Build dashboards and reporting that give the team and leadership real visibility into response times, coverage, and risk reduction. Work cross-functionally with engineers who don't have a security background, translating threat models into changes they can actually ship. What you bring You'll thrive in this role if you have: 10+ years of experience in security operations, incident response, or a closely related discipline, with a proven track record of materialised risk reduction through monetary impact, incidents contained, forensics that changed outcomes. A strong development and engineering background. You are comfortable writing the automation, not just specifying it. Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design. Experience in scale-up environments, where you've built capability rather tha…